As reported by SecurityAffairs, CISA has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, all linked to a broader espionage campaign attributed to China-based Integrity Technology Group. A joint advisory from seven nations accompanies the update, and the DOJ has seized two tools — Microscan and FishHub — allegedly used to scan for vulnerable systems and facilitate spear-phishing operations.

Security Impact: As reported by SecurityAffairs, CISA has added five vulnerabilities to its Known Exploited Vulnerabilities (KEV) catalog, all linked to a broader espionage campaign attributed to China-based Integrity Technology Group.

The most striking takeaway isn't the sophistication of the exploitation. It's the age of the flaws. CVE-2015-3306 and CVE-2015-5477 have been public knowledge for over eleven years. Their continued presence in exploitable deployments suggests that legacy infrastructure — FTP servers, DNS resolvers, outdated application frameworks — remains critically undermanaged in many organizations.

KEV Additions at a Glance

CVEProductCVSSSeverityFlaw TypeExploited
CVE-2015-3306ProFTPD10.0CriticalAccess control bypass (SITE CPFR/CPTO)Yes — in the wild
CVE-2021-3199ONLYOFFICE Docs9.8CriticalPath traversal with JWT enabledYes — in the wild
CVE-2016-3081Apache Struts8.1HighCommand injection (DMI enabled)Yes — in the wild
CVE-2023-22894Strapi7.2HighCleartext sensitive data exposureYes — in the wild
CVE-2015-5477ISC BIND7.5HighDoS via TKEY query assertionYes — in the wild

Why This Matters

Three of these five vulnerabilities are old enough to predate modern vulnerability management programs. The fact that nation-state actors are still finding exploitable instances tells us two things: first, that scanning tools like the seized Microscan are effective at finding unpatched edge devices and services exposed to the internet; second, that many organizations lack visibility into their external attack surface and cannot answer the simple question, do we even run ProFTPD or an older BIND resolver?

The ONLYOFFICE Docs vulnerability (CVE-2021-3199) deserves particular attention. Document collaboration platforms are increasingly internet-facing, and a 9.8 CVSS path traversal that enables remote code execution when JWT is enabled is a dangerous combination. Many SaaS-adjacent deployments may not even realize they're running a vulnerable version.

Broader Implications

Why This Matters
Legacy exposure is a tactical advantage for adversaries. Threat actors don't need zero-days when decade-old criticals remain unpatched. Defense programs must include asset inventory and decommissioning, not just patching.
The seven-nation joint advisory signals coordinated attribution pressure on China-linked firms. Integrity Technology Group's designation as a commercial cybersecurity company used as a front for state-aligned operations mirrors the pattern seen with other Chinese firms sanctioned in recent years.
Tool seizure (Microscan, FishHub) may temporarily disrupt operations but won't eliminate the capability. Scanning infrastructure is trivially replaceable; defenders should assume continued targeting.

Shield53 Recommendations

Immediate Actions

  • Inventory and patch all five CVEs within the CISA KEV remediation window (typically 14 days for federal agencies; all organizations should treat as urgent).
  • ProFTPD (CVE-2015-3306): Upgrade to version 1.3.6c or later. If upgrade is impossible, disable the SITE CPFR/SITE CPTO commands or restrict access via Limit directives in the ProFTPD configuration. Check for signs of prior compromise — unauthorized file modifications, unusual SFTP sessions.
  • ONLYOFFICE Docs (CVE-2021-3199): Update to a patched version. Audit JWT configuration and review upload directories for unexpected files indicating prior traversal exploitation.
  • Apache Struts (CVE-2016-3081): Upgrade to Struts 2.3.20.3 or 2.5.x or later. Ensure Dynamic Method Invocation is disabled (it's off by default in modern versions — verify your config hasn't re-enabled it).
  • Strapi (CVE-2023-22894): Upgrade to a patched version. Rotate any credentials or secrets that may have been exposed in cleartext. Review admin panel access logs for suspicious query patterns.
  • ISC BIND (CVE-2015-5477): Update to BIND 9.10.3-P2 or later. Restrict TKEY queries to trusted hosts only. Monitor resolver availability for unexpected restarts or crashes.

Detection & Hunting

  • Search perimeter logs and SIEM for the following indicators: ProFTPD SITE CPFR/SITE CPTO command sequences; BIND resolver crash events correlated with TKEY queries; Apache Struts requests containing method: prefixes; Strapi admin API calls with unusual query filter parameters.
  • Review external-facing services for exposure of ONLYOFFICE, Strapi admin panels, ProFTPD, and BIND resolvers. If these services don't need to be internet-facing, move them behind a VPN or zero-trust gateway immediately.
  • Hunt for post-exploitation artifacts: credential dumps, email exfiltration, unusual VPN sessions — all consistent with the described campaign's tactics.

The real lesson here isn't that adversaries are using old vulnerabilities — it's that we keep letting them work. If your organization can't produce a credible inventory of internet-facing services within hours, you're operating at a disadvantage that no SOC tool can fix.